Icarus Group Exploits Klue OAuth Breach to Steal Salesforce Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In June 2026, a significant security incident involving Klue, a market intelligence platform, allowed the Icarus threat actor group to exfiltrate Salesforce CRM data from multiple organizations, including Huntress. The attack exploited OAuth tokens from Klue's Battlecards integration, enabling unauthorized access to customer Salesforce instances. The breach began on June 12, 2026, and involved automated scripts that queried Salesforce's REST API for nearly 24 hours, leading to the theft of sensitive CRM data. Salesforce has since disabled the Klue Battlecards integration to mitigate further risks. Both Huntress and ReliaQuest confirmed their data was compromised, and affected organizations are now facing extortion demands from the attackers. The full scope of the impact is still being assessed, but it highlights the vulnerabilities associated with third-party integrations.
Key Points: • The Icarus group exploited a Klue OAuth breach to steal Salesforce data. • Attackers used automated scripts to exfiltrate data over a 24-hour period. • Salesforce has disabled the Klue Battlecards integration in response to the breach.